Skip to content

Commit d20553c

Browse files
committed
strip forbidden characters from the sql query
1 parent 00a96ab commit d20553c

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

src/forum.nim

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1607,7 +1607,8 @@ routes:
16071607

16081608
get "/search.json":
16091609
cond "q" in request.params
1610-
let q = @"q"
1610+
let forbiddenSymbols = @[("(", ""), (")", "")]
1611+
let q = @"q".multiReplace(forbiddenSymbols)
16111612
cond q.len > 0
16121613

16131614
var results: seq[SearchResult] = @[]

0 commit comments

Comments
 (0)